CWE-79
MITRE ↗Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
Multiple stored cross-site scripting (XSS) vulnerabilities on AdTran NetVanta 3120 18.01.01.00.E devices allow remote at
An issue was discovered in Archer Platform 6 before 2024.06. Authenticated users can achieve HTML content injection. A r
The SportsPress WordPress plugin before 2.7.22 does not sanitise and escape some of its settings, which could allow hig
The WANotifier WordPress plugin before 2.6.1 does not sanitise and escape some of its settings, which could allow high
The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which c
The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin
Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in the generate dashboard board ins
The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow
The Chatbot for WordPress by Collect.chat ⚡️ WordPress plugin before 2.4.4 does not sanitise and escape some of its sett
The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow user
The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back i
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to cond
A Stored Cross Site Scripting (XSS) vulnerability was found in "/smsa/add_class_submit.php" in Responsive School Managem
The Search & Filter Pro WordPress plugin before 2.5.18 does not sanitise and escape some of its settings, which could al
Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue a
Concrete CMS versions 9.0.0 to 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer when user input is s
The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4
Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in Board instances. A rogue adminis
The Generate Images WordPress plugin before 5.2.8 does not sanitise and escape some of its settings, which could allow
IBM Common Licensing 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to em
symphonycms <=2.7.10 is vulnerable to Cross Site Scripting (XSS) in the Comment component for articles.
A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel
The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could al
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t
A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulner
Cross Site Scripting vulnerability in Teldats Router RS123, RS123w allows attacker to execute arbitrary code via the cmd
The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high
The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of i
A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted
The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and e
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some o
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some o
The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow hig
The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high pri
The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow hi
Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in
The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could a
The Starbox WordPress plugin before 3.5.2 does not sanitise and escape some of its settings, which could allow high pri
eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code v
The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings
The Logo Slider WordPress plugin before 3.6.9 does not sanitise and escape some of its settings, which could allow high
The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which cou
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Give
The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, w
The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, w
The Carousel Slider WordPress plugin before 2.2.4 does not sanitise and escape some of its settings, which could allow h
The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin
phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-det
Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block. A r
The Logo Manager For Enamad WordPress plugin through 0.7.1 does not sanitise and escape in its widgets settings, which c
Frequently Asked Questions
What is CWE-79?
CWE-79 (Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-79?
There are 53,037 CVE records associated with CWE-79 in our database. Of these, 560 are critical severity, 4909 are high severity, and 31199 are medium severity.
How can I protect against CWE-79 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-79 using AI-powered security agents.
Detect CWE-79 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of input during web page generation (cross-site scripting) vulnerabilities across your infrastructure.
Get Started